CVE List

Id CVE No. Status Description Phase Votes Comments Actions
8105  CVE-2003-1281  Candidate  cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files.  Assigned (20051116)  None (candidate not yet proposed)    View
8104  CVE-2003-1280  Candidate  Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads.  Assigned (20051116)  None (candidate not yet proposed)    View
8103  CVE-2003-1279  Candidate  S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html.  Assigned (20051116)  None (candidate not yet proposed)    View
8102  CVE-2003-1278  Candidate  Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags.  Assigned (20051116)  None (candidate not yet proposed)    View
8101  CVE-2003-1277  Candidate  Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html  Assigned (20051116)  None (candidate not yet proposed)    View

Page 19323 of 20943, showing 5 records out of 104715 total, starting on record 96611, ending on 96615

Actions